Skip to content

docs: document the external services the bundled editor can reach - #126

Merged
erseco merged 1 commit into
mainfrom
feature/document-external-services
Sep 26, 2026
Merged

erseco merged 1 commit into
mainfrom
feature/document-external-services

Conversation

@erseco

@erseco erseco commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

WordPress.org asks plugins to disclose the third-party services they contact. This adds a short == External services == section that lists only genuine services, and only when they are used: content an author adds.

Service When Terms / Privacy
YouTube YouTube video embedded or used by a video iDevice (IFrame Player API) youtube.com/t/terms, policies.google.com/privacy
Vimeo Vimeo video embedded vimeo.com/terms, vimeo.com/privacy
GeoGebra GeoGebra iDevice: material id sent to api/json.php; applet loaded when shown geogebra.org/tos, geogebra.org/privacy
EducaMadrid Mediateca Mediateca media selected; its player script for Mediateca interactive videos mediateca.educa.madrid.org/aviso-legal

It closes with one sentence covering anything else an author embeds (Google Drive, H5P, other sites).

What is intentionally not listed

The previous version of this PR also disclosed remote code and assets. Those are being removed from the bundled editor or shipped inside it instead, because Guideline 8 does not allow them to be disclosed away:

  • Bundled into the package: jsPDF (jsDelivr), the Draco/KTX2 decoders (gstatic) and the abcjs soundfonts.
  • Removed from the editor: the dead Twitter/Facebook lightbox widgets and Google Translate; dummyimage.com and the YouTube examples in the TinyMCE templates; the JW Player script that loaded on every interactive-video editor open (it now loads only when a Mediateca video is chosen).
  • Never requested: MathJax fonts and speech (both local or disabled), RCSB/PubChem (the iDevice only loads uploaded files) and H5P (only resized, never loaded).

Those editor changes are in exelearning/exelearning (#2446 and follow-ups). Merge this PR together with the .editor-version bump to the editor release that contains them, so the readme describes the package that is actually shipped.

Changelog: one line for this PR only. The entries for #124 and #125 were removed from here.

@github-actions

Copy link
Copy Markdown
Contributor

Test in WordPress Playground

Test the plugin with the code from this branch:

Preview in WordPress Playground

ℹ️ The eXeLearning editor is fetched from the shared release and unpacked into the plugin when the playground boots, so the first load may take a few extra seconds. ELP upload, shortcode, Gutenberg block and preview work normally.

@codecov-commenter

codecov-commenter commented Sep 18, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 96.40%. Comparing base (25b98a0) to head (46a18d9).

Additional details and impacted files
@@            Coverage Diff            @@
##               main     #126   +/-   ##
=========================================
  Coverage     96.40%   96.40%           
  Complexity      827      827           
=========================================
  Files            36       36           
  Lines          4233     4233           
=========================================
  Hits           4081     4081           
  Misses          152      152           
Flag Coverage Δ
javascript 95.71% <ø> (ø)
php 96.63% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

WordPress.org asks plugins to disclose third-party services they contact.
List the four the bundled editor uses for content an author adds: YouTube,
Vimeo, GeoGebra and EducaMadrid Mediateca, with when the request happens,
what the provider receives, and each service's terms and privacy policy.
Anything else an author embeds is covered by one closing sentence.
@erseco
erseco force-pushed the feature/document-external-services branch from 7bb3d5f to 46a18d9 Compare September 26, 2026 10:22
@erseco
erseco merged commit 6710a4b into main Sep 26, 2026
5 checks passed
@erseco
erseco deleted the feature/document-external-services branch September 26, 2026 11:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants